Söz
Neden bize güvenmemelisiniz.
Tuhaf bir başlık, biliyoruz. Ama bir veri egemenliği ürününde
"bize güvenin" cümlesi başlı başına bir kırmızı bayraktır.
Verilerinizi koruduğunu söyleyen bir sistemi, o sistemi yazan kişiye duyduğunuz güvenle
kullanamazsınız. Bunun tek dürüst çözümü vardır: kodu göstermek.
Bu yüzden paylaştığımız her şey okunabilir. Uzaktan erişim kapısı yok,
gizli hesap yok, "destek amaçlı" arka kapı yok, telemetri yok. Bunu iddia etmiyoruz —
okunabilir hâle getiriyoruz. Kendiniz bakın; bakacak birini tanımıyorsanız,
bakacak birini tutun. Doğru tepki budur.
☰ FELSEFE 01
Bilgi insanlık içindir
Kapatılan her bilgi, birilerinin ayrıcalığına dönüşür. Sistemin kendisini ücretsiz
vermemizin sebebi budur. Bunun karşılığında sizden bir şey almıyoruz — hesap, e-posta,
kullanım verisi, hiçbiri.
☰ FELSEFE 02
Veri egemenliği
Bir kurumun ürettiği bilgi, o kuruma aittir. Sunucunun coğrafyası değil,
anahtarın kimde olduğu belirleyicidir. Kurduğumuz sistemlerde anahtar
her zaman sizde kalır — bizde kopyası olmaz.
Ve yapmadığımız şeyler: Kırılmaz olduğumuzu söylemiyoruz — böyle bir şey yok.
Sizi devlet çapında bir istihbarat servisinden koruyacağımızı iddia etmiyoruz. Sihirli bir
şifreleme bulduğumuzu söylemiyoruz; dünyanın denetlediği standartları kullanıyoruz.
Söylediğimiz tek şey şu: verinizin nerede olduğunu, kimin eriştiğini ve
kime gitmediğini bilirsiniz. Bu, bugün piyasadaki çoğu seçenekten fazlasıdır.
Kendi bağımlılıklarımız.
Veri egemenliğini anlatan bir sayfanın en kolay yalanı, kendi bağımlılıklarını
göstermemektir. O yüzden burada açıkça yazıyoruz.
Şu okuduğunuz sayfa, halka açık internete bir CDN/tünel sağlayıcısı üzerinden
ulaşıyor. Sabit IP'si ve saldırı koruması olmayan iki kişilik bir ekibin, kendi
makinesinden güvenli biçimde yayın yapabilmesinin pratik yolu buydu. Bunu saklamıyoruz.
Ama ayrımı doğru kurmak şart, çünkü ikisi aynı şey değil:
▣ VERİ KATMANI
Bağımsız — dışarıdan geçmez
Dosyalarınız, yedekleriniz, iç yazışmalarınız ve cihazlar arası trafiğiniz
HİSAR ağı üzerinden, uçtan uca şifreli akar. Bu trafik hiçbir dış
sağlayıcıya uğramaz; anahtarlar yalnızca sizin düğümlerinizde bulunur. Sistemin
asıl vaadi burasıdır ve burası bağımsızdır.
▣ YAYIN KATMANI
Şu an bağımlı — ve dürüst maruziyet
Halka açık web trafiği (bu sayfa ve üzerindeki iletişim formu dâhil) dış
bir sağlayıcı üzerinden geçer. Bu mimaride şifreli bağlantı sağlayıcıda sonlanır — yani
teknik olarak orada görülebilir. Bu yüzden formda size
"gizli bilgi paylaşmayın" yazıyoruz. Boş bir nezaket cümlesi değil,
mimarinin gereği.
Yol haritamız: yayın katmanını da kendi altyapımıza almak — kendi sınır
düğümümüz, kendi saldırı koruma ve sertifika zincirimiz. Planlama yapıldı, çalışma sırada.
Bittiğinde bunu iddia olarak değil, yine böyle bir bölümde kanıtla yazacağız.
Bugün nerede, nereye gidiyoruz.
Bu sayfayı her geliştirmede yeniden yazmıyoruz. Bunun yerine iki sütun
tutuyoruz: bugün çalışan şey ve hedeflenen şey.
İkisini karıştırmıyoruz — pazarlama dilinde en sık yapılan şey tam olarak budur ve
bir egemenlik ürününde affedilmez.
| Alan | Bugün çalışan | Hedef |
| Yedekleme |
Aynı veri birden fazla fiziksel diske çoğaltılıyor, kopyalar düzenli doğrulanıyor |
Aynalı disk havuzu + anlık görüntü (snapshot) düzeni: disk arızasında kesintisiz devam, yanlışlıkla silmede geriye dönüş |
| Yayın katmanı |
Halka açık trafik dış bir CDN/tünel sağlayıcısından geçiyor |
Kendi TLS sertifikamız, kendi güvenlik duvarımız, kendi kapı bekçimiz. Bağlantı üstverisi dışarıya çıkmaz. Hattın kaldıramayacağı hacimsel saldırılar için geri dönüş planı önceden yazılı tutulur — dayanamayınca geçici geri çekilmek utanç değil, mühendisliktir |
| Sunucu adresi |
Sağlayıcının arkasında gizli |
Kendi sınır düğümümüz üzerinden maskelenir — maskeyi de biz işletiriz. Trafik orada çözülmez, yalnızca aktarılır |
| Bant genişliği |
Statik içerik dış sağlayıcıda önbelleğe alınıyor |
Kendi önbellek ve içerik dağıtım katmanımız — ziyaretçi arttıkça faturanın değil, yalnızca hattın konuştuğu bir düzen |
| Yasal uyum |
Yürürlükteki mevzuata uygun çalışılıyor |
Ayrımı mimariye yazmak: yasanın istediği bağlantı kayıtları tutulur, içerik uçtan uca şifreli kalır ve tarafımızca okunamaz. İkisi birbirinin alternatifi değildir |
| Süreklilik |
Ana düğüm tek başına ayakta |
İkinci düğüm devralır — tek makine, tek arıza noktası olmaktan çıkar |
| Dağıtım |
Tek dosya kurulabilir imaj yayında — indir, USB'ye yaz, kur |
İmzalı sürüm akışı ve güvenli güncelleme kanalı: kurulu sistem kendini doğrulayarak güncellesin — Linux uzmanlığı gerekmeden |
| Yerel yapay zekâ |
GPU düğümü ağa dâhil, modeller yerelde çalışıyor |
Kendi arşivinize soru soran, binadan hiç çıkmayan kurumsal asistan |
| Ekip ölçeği |
İki geliştirici |
Kurulum, destek ve sertifikasyonu ölçekleyebilecek bir yapı (yol 03) |
Hedef sütunundaki hiçbir şey "belki" değil — hepsi planlı ve sırada. Ama
bugün çalışmıyorsa, bugün çalışıyormuş gibi yazmıyoruz. Bu sayfada okuduğunuz
ve "çalışıyor" denen her şeyi, size kurduğumuz sistemde kendi ellerinizle test
edebilirsiniz. Edemediğiniz bir şey varsa, o zaten bu tablonun sağ sütununda durur.
Bugün %100 bağımsız değiliz ve bunu söylemek işimize gelmiyor.
Yine de yazıyoruz — çünkü bağımlılığını gizleyen bir egemenlik ürünü,
anlattığı her şeyi çürütür. Sizden de tam olarak bu soruyu sormanızı istiyoruz:
"Peki sizin bağımlılıklarınız ne?" Cevap veremeyen satıcıya güvenmeyin.
Our commitment
Why you should not trust us.
An odd headline, we know. But in a data-sovereignty product,
the sentence "trust us" is itself a red flag.
You cannot use a system that claims to protect your data on the strength of your faith in
whoever wrote it. There is only one honest solution: show the code.
So everything we ship is readable. No remote access door, no hidden account,
no "for support purposes" backdoor, no telemetry. We are not asking you to believe that —
we are making it readable. Check it yourself; and if you don't know anyone who
can, hire someone who can. That is the correct reflex.
☰ PHILOSOPHY 01
Knowledge belongs to humanity
Every piece of knowledge locked away becomes someone's privilege. That is why the system
itself is free. We take nothing in return — no account, no email, no usage data.
☰ PHILOSOPHY 02
Data sovereignty
The knowledge an organisation produces belongs to that organisation. What decides ownership
is not the server's geography but who holds the key. In systems we build,
the key always stays with you — we keep no copy.
And what we do not claim: We are not unbreakable — nothing is. We do not claim
to shield you from a nation-state intelligence service. We have not invented magic cryptography;
we use the standards the world audits. What we do say is this:
you will know where your data is, who reaches it, and where it does not go.
Today, that is already more than most options on the market offer.
Our own dependencies.
The easiest lie for a page about data sovereignty to tell is
to not show its own dependencies. So here they are, in plain sight.
The page you are reading reaches the public internet through a CDN/tunnel
provider. For a two-person team with no static IP and no attack protection, that was
the practical way to publish safely from our own machine. We are not hiding it.
But the distinction matters, because these are not the same thing:
▣ DATA LAYER
Independent — nothing passes outside
Your files, backups, internal correspondence and device-to-device traffic flow
over the HİSAR network, end-to-end encrypted. That traffic touches no
external provider; the keys exist only on your nodes. This is
the system's actual promise — and this part is independent.
▣ PUBLISHING LAYER
Currently dependent — honest exposure
Public web traffic (this page, including the contact form on it) passes
through an external provider. In this architecture the encrypted connection terminates at
that provider — meaning it is technically visible there. That is why the
form tells you "don't share confidential material." Not a
pleasantry — an architectural fact.
Our roadmap: bring the publishing layer in-house too — our own edge node, our
own attack mitigation and certificate chain. It is planned and queued. When it is done, we will
write it up not as a claim, but with proof, in a section exactly like this one.
Where we are, where we're going.
We don't rewrite this page with every improvement. Instead we keep two columns:
what works today and what is targeted. We never
blur the two — blurring them is the single most common move in marketing language, and in a
sovereignty product it is unforgivable.
| Area | Working today | Target |
| Backup |
The same data replicated across multiple physical disks, copies verified on a schedule |
A mirrored disk pool plus snapshots: uninterrupted operation through a disk failure, and rollback after an accidental deletion |
| Publishing layer |
Public traffic passes through an external CDN/tunnel provider |
Our own TLS certificates, our own firewall, our own gatekeeper. Connection metadata never leaves. For volumetric attacks beyond the line's capacity a fallback runbook is kept written in advance — retreating temporarily when you can't absorb it is engineering, not shame |
| Server address |
Hidden behind the provider |
Masked through our own edge node — and we operate the mask. Traffic is relayed there, never decrypted |
| Bandwidth |
Static content cached at the external provider |
Our own caching and delivery layer — an arrangement where more visitors means more load on the line, not on an invoice |
| Legal compliance |
Operating in line with applicable regulation |
Writing the distinction into the architecture: the connection records the law requires are kept, while content stays end-to-end encrypted and unreadable to us. These are not alternatives to one another |
| Continuity |
The primary node stands alone |
A second node takes over — one machine stops being a single point of failure |
| Distribution |
A single installable image is published — download, write to USB, install |
A signed release stream and a secure update channel: an installed system that verifies and updates itself — no Linux expertise required |
| Local AI |
GPU node on the network, models running locally |
An assistant that answers questions about your own archive and never leaves the building |
| Team scale |
Two developers |
A structure that can scale installation, support and certification (route 03) |
Nothing in the target column is a "maybe" — it is all planned and queued. But
if it doesn't work today, we don't write it as though it does. Everything on
this page described as working, you can test with your own hands on the system
we build for you. Anything you can't test is, by definition, in the right-hand column.
We are not 100% independent today, and saying so does not serve our interests.
We say it anyway — because a sovereignty product that hides its dependencies
refutes everything else it claims. And we want you to ask us exactly this question:
"So what are your dependencies?" Never trust a vendor who can't answer it.